> Source: [sk169258](https://support.checkpoint.com/results/sk/sk169258)

# sk169258 - How to collect VPN logs from the Endpoint Security Client / Endpoint Security VPN

| Property | Value |
|----------|-------|
| Solution ID | sk169258 |
| Date Created | 2020-09-11 |
| Last Modified | 2025-01-02 |
| Technical Level | General |
| OS | Windows |
| Platform | Intel/PC |

## Solution

### **Procedure in the Client GUI:**

Show / Hide this section  
1. In the system tray, right-click the Yellow/Green Padlock icon.  

2. In the menu, click the applicable option:
   * In an **Endpoint Security Client** (Full Suite), click **Display Overview**.
   * In an **Endpoint Security VPN** Client (VPN only), click **VPN Options** .  
     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk169258/Tasktray202102230835311.png)
3. In an Endpoint Security Client (Full Suite):  
   Click **Remote Access VPN** \> **Manage settings** .  

4. Click the **Advanced** tab.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk169258/2021-02-23 08_25_09-172202102230836252.25.140.90 - Remote Desktop Connection (Work Resources).png)
5. Select **Enable Logging** (if needed, select the logging level **Extended** ).  

6. Click **Save \& Close** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk169258/2021-02-23 08_25_22-172202102230837013.25.140.90 - Remote Desktop Connection (Work Resources).png)  

7. Replicate issue.  

8. Repeat Steps 1-4 to get to the **Advanced** tab.  

9. Click **Collect Logs** .  

10. When the logs are collected, a Windows File Explorer window opens and shows the contents of archive Cabinet File "**trlogs_\<DATE\>_\<TIME\>** " that contains the log files.  
    **Example** (click on the screenshot to enlarge it):  
    ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk169258/log1202102230850233.png)  

11. In the top address bar, click the folder name that appears in front of the "**trlogs_\<DATE\>_\<TIME\>** ".  
    Get the Cabinet File that contains the log files.  
    **Example** (click on the screenshot to enlarge it):  
    ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk169258/log2202102230851004.png)  

12. **Important:** In the Client GUI, clear **Enable Logging**.

### **Procedure in the Client Command Line:**

Show / Hide this section  
1. Open Windows Command Prompt.  

2. Go to the applicable folder:
   1. For an Endpoint Security Client (Full Suite):  
      `cd /d "c:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Connect\"`
   2. For an Endpoint Security VPN Client (VPN only):  
      `cd /d "c:\Program Files (x86)\CheckPoint\Endpoint Connect\"`  

3. Enable the logging:  
   `trac.exe enable_log`  

4. Replicate the issue.  

5. Collect the logs:`trac.exe collect_logs`
6. When the logs are collected, a Windows File Explorer window opens and shows the contents of archive Cabinet File "**trlogs_\<DATE\>_\<TIME\>** " that contains the log files.  
   **Example** (click on the screenshot to enlarge it):  
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk169258/log1202102230850233.png)  

7. In the top address bar, click the folder name that appears in front of the "**trlogs_\<DATE\>_\<TIME\>** ".  
   Get the Cabinet File that contains the log files.  
   **Example** (click on the screenshot to enlarge it):  
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk169258/log2202102230851004.png)  

8. **Important:** Disable the logging:  
   `trac.exe disable_log`

**Related Solutions:**

* [sk90445 - How to collect a CPinfo from the Endpoint Security Client](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90445)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
